CVE-2024-20321
A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an
Description
A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because eBGP traffic is mapped to a shared hardware rate-limiter queue. An attacker could exploit this vulnerability by sending large amounts of network traffic with certain characteristics through an affected device. A successful exploit could allow the attacker to cause eBGP neighbor sessions to be dropped, leading to a DoS condition in the network.
Weakness: CWE-400
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco NX-OS Software | Routing & Switching | cna-assigner |
Vendor-reported products (2)
- Cisco · Cisco NX-OS Software
- cisco · nx-os
Vendor advisory
cisco-sa-nxos-ebgp-dos-L3QCwVJ
Cisco NX-OS Software External Border Gateway Protocol Denial of Service Vulnerability
Cisco’s rating: High (advisory CVSS 8.6) · Published Feb 28, 2024
Bug IDs: CSCwh09703 , CSCwh96478
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from